osquery.conf "packs": { "osquery-monitoring": "/usr/share/osquery/packs/osquery-monitoring.conf", "incident-response , "packs": { "osquery-monitoring": "/usr/share/osquery/packs/osquery-monitoring.conf", "incident-response packs/fim.conf", "osquery-monitoring": "/usr/share/osquery/packs/osquery-monitoring.conf", "incident-response
原文链接: https://blog.lawrencejones.dev/incident-response/index.html
wing:client-acme、wing:client-globex),适用于面向多个外部客户的 SaaS 服务模式;按功能维度划分(如 wing:architecture-decisions、wing:incident-response